Network
Please note the following guidelines for the secure operation of a TwinCAT HMI application:
- The TwinCAT HMI Server should not be directly accessible from the Internet. If a remote connection is necessary, it can be established securely via a VPN (Virtual Private Network).
- Remote access should only take place via HTTPS (Hypertext Transfer Protocol Secure). Unencrypted access via HTTP is permitted only locally. The HMI server issues self-signed certificates. Alternatively, you can configure or generate your own certificates.
- Enable the firewall on the operating system running the HMI server and allow access only to the HTTPS endpoints via TCP.